Examine this output from a debug flow:
Why did the FortiGate drop the packet?
Correct Answer:
D
https://kb.fortinet.com/kb/documentLink.do?externalID=13900 https://www.fortinetguru.com/2016/03/what-is-policy-id-0-and-why-lot-of-denied-traffic-on-this-policy/
What are two characteristics of FortiGate HA cluster virtual IP addresses? (Choose two.)
Correct Answer:
AD
Fortigate Infrastructure 7.2 Study Guide page 301 FortiGate Infrastructure 7.2 Study Guide (p.301):
"FGCP automatically assigns the heartbeat IP addresses based on the serial number of each device. The IP address 169.254.0.1 is assigned to the device with the highest serial number."
"A change in the heartbeat IP addresses may happen when a FortiGate device joins or leaves the cluster." "The HA cluster uses the heartbeat IP addresses to distinguish the cluster members and synchronize data." https://networkinterview.com/fortigate-ha-high-availability/
Which statement about the deployment of the Security Fabric in a multi-VDOM environment is true?
Correct Answer:
A
FortiGate Security 7.2 Study Guide (p.436): "When you configure FortiGate devices in multi-vdom mode and add them to the Security Fabric, each VDOM with its assigned ports is displayed when one or more devices are detected. Only the ports with discovered and connected devices appear in the Security Fabric view and, because of this, you must enable Device Detection on ports you want to have displayed in the Security Fabric. VDOMs without ports with connected devices are not displayed. All VDOMs configured must be part of a single Security Fabric."
Which of the following are purposes of NAT traversal in IPsec? (Choose two.)
Correct Answer:
AC
Which statement describes a characteristic of automation stitches?
Correct Answer:
C
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/351998/creating-automation-stitches